Lucene search

K
cveMitreCVE-2022-34551
HistoryJul 27, 2022 - 2:15 p.m.

CVE-2022-34551

2022-07-2714:15:08
CWE-22
mitre
web.nvd.nist.gov
33
5
cve-2022-34551
sims v1.0
path traversal
attachments
nvd

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

26.8%

Sims v1.0 was discovered to allow path traversal when downloading attachments.

Affected configurations

Nvd
Node
sims_projectsimsMatch1.0
VendorProductVersionCPE
sims_projectsims1.0cpe:2.3:a:sims_project:sims:1.0:*:*:*:*:*:*:*

Social References

More

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

26.8%

Related for CVE-2022-34551